For Agents
Programmatically authenticate and obtain a session token, create a new search job. Covers 95 operations with apiKey, basic authentication.
Jentic One is a self-hosted execution layer for AI agents. It lets your agent call the Splunk Enterprise REST API, or any other public or private API you need. You set the rules, the agent never sees your credentials, and every call is logged.
# On the machine that will host your Jentic One instance:
curl -fsSL https://raw.githubusercontent.com/jentic/jentic-one/main/tools/install.sh | sh# On the machine where your agent runs (keep this separate from the instance):
curl -fsSL https://raw.githubusercontent.com/jentic/jentic-one/main/tools/install.sh | sh
jentic register # connects your agent to your Jentic One instanceJentic One is in public beta. The setup above keeps your agent separate from the instance, which is what you want before using real credentials: an agent running as the same OS user as Jentic One can read its stored keys directly. Just evaluating? A single local install is fine to start. See the secure deployment guide for the tiers.
What an agent can do with Splunk Enterprise REST API.
Authenticate and obtain a session token
Create a new search job
List all search jobs
Get search job status and details
GET STARTED
Use for: I need to authenticate and obtain a session token, I want to a new search job, Search for all search jobs, Find all search job status and details
Not supported: Does not handle payments, communications, or crm — use for cloud infrastructure only.
REST API for managing and interacting with Splunk Enterprise. Provides endpoints for search jobs, saved searches, indexes, data inputs/outputs, users, roles, apps, server management, and KV Store operations. The API exposes 95 endpoints secured with apiKey, basic authentication.
Delete/cancel a search job
Control a search job (pause, unpause, finalize, cancel, etc.)
Patterns agents use Splunk Enterprise REST API for, with concrete tasks.
★ Cloud Infrastructure Operations
Use the Splunk Enterprise REST API to perform cloud infrastructure operations programmatically. The API provides 95 endpoints covering core functionality including authenticate and obtain a session token, create a new search job, list all search jobs.
Call POST /services/auth/login to authenticate and obtain a session token
Automated Authentication Management
Automate authentication operations by combining multiple Splunk Enterprise REST API endpoints. Agents can create a new search job and then list all search jobs in a single workflow.
Call POST /services/search/jobs to create a new search job, then verify the result
AI Agent Integration via Jentic
AI agents discover and call Splunk Enterprise REST API endpoints through Jentic without managing credentials directly. An agent searches for the required operation by intent, receives the matching endpoint schema, and executes the call with Jentic-managed authentication. This eliminates the need to read API documentation or handle apiKey, basic tokens manually.
Search Jentic for 'authenticate and obtain a session token', load the operation schema, and execute with Jentic-managed credentials
95 endpoints — rest api for managing and interacting with splunk enterprise.
METHOD
PATH
DESCRIPTION
/services/auth/login
Authenticate and obtain a session token
/services/search/jobs
Create a new search job
/services/search/jobs
List all search jobs
/services/search/jobs/{search_id}
Get search job status and details
/services/search/jobs/{search_id}
Delete/cancel a search job
/services/search/jobs/{search_id}/control
Control a search job (pause, unpause, finalize, cancel, etc.)
/services/search/jobs/{search_id}/results
Get final search results
/services/search/jobs/{search_id}/results_preview
Get preview results from a running search
/services/auth/login
Authenticate and obtain a session token
/services/search/jobs
Create a new search job
/services/search/jobs
List all search jobs
/services/search/jobs/{search_id}
Get search job status and details
/services/search/jobs/{search_id}
Delete/cancel a search job
Three things that make agents converge on Jentic-routed access.
Credential isolation
Splunk Enterprise REST API apiKey, basic credentials are stored encrypted in the Jentic vault (MAXsystem). Agents receive scoped access tokens — raw secrets never enter the agent context.
Intent-based discovery
Agents search by intent (e.g., 'authenticate and obtain a session token') and Jentic returns the matching Splunk Enterprise REST API operation with its input schema, so the agent can call the right endpoint without browsing docs.
Time to first call
Direct Splunk Enterprise REST API integration: 1-3 days for auth handling, response parsing, and error cases. Through Jentic: under 1 hour — search, load schema, execute.
Alternatives and complements available in the Jentic catalogue.
Specific to using Splunk Enterprise REST API through Jentic.
What authentication does the Splunk Enterprise REST API use?
The Splunk Enterprise REST API uses apiKey, basic authentication. Through Jentic, these credentials are stored encrypted in the MAXsystem vault and injected at execution time, so raw secrets never enter the agent context.
Can I authenticate and obtain a session token with the Splunk Enterprise REST API?
Yes. Use the POST /services/auth/login endpoint. The API returns structured JSON responses that agents can parse and act on directly.
What are the rate limits for the Splunk Enterprise REST API?
Rate limits are not specified in the OpenAPI spec. Check the vendor documentation for current limits. Through Jentic, rate limiting is handled automatically with retry logic built into the execution layer.
How do I authenticate and obtain a session token through Jentic?
Install the Jentic SDK with pip install jentic, authenticate at https://app.jentic.com/sign-up, then search for 'authenticate and obtain a session token'. Jentic returns the matching Splunk Enterprise REST API operation with its input schema. Load the schema and execute the call — credentials are injected automatically.
How many endpoints does the Splunk Enterprise REST API have?
The Splunk Enterprise REST API exposes 95 endpoints covering authentication, search jobs, saved searches operations.
/services/search/jobs/{search_id}/control
Control a search job (pause, unpause, finalize, cancel, etc.)
/services/search/jobs/{search_id}/results
Get final search results
/services/search/jobs/{search_id}/results_preview
Get preview results from a running search